Close Menu
  • Home
  • Fitness
  • Health
    • Healthcare
    • Healthy Food
    • Healthy Lifestyle
  • Nutrition
  • Running
  • Weight Loss
    • Diet
  • Yoga

Subscribe to Updates

Get the latest creative news from Shapeperfeito about health, fitness and healthy lifestyle.

Please enable JavaScript in your browser to complete this form.
Loading
What's Hot

Trilivy Assessment: Optavia’s New Identification

July 29, 2026

Merrell MTL SpeedArc Peak Assessment – iRunFar

July 29, 2026

Breathe in Yoga: When to Inhale and Exhale (Pranayama Fundamentals) – Fitsri Yoga

July 29, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Shape Perfeito
  • Home
  • Fitness
  • Health
    • Healthcare
    • Healthy Food
    • Healthy Lifestyle
  • Nutrition
  • Running
  • Weight Loss
    • Diet
  • Yoga
Shape Perfeito
Home»Healthcare»SharpHound Recon Assault – How AI enhanced the menace hunt
Healthcare

SharpHound Recon Assault – How AI enhanced the menace hunt

Shape PerfeitoBy Shape PerfeitoJuly 7, 2026No Comments8 Mins Read
SharpHound Recon Assault – How AI enhanced the menace hunt
Share
Facebook Twitter Reddit Telegram Pinterest Email


Cisco Reside AMER 2026 was the right place to place the Agentic SOC to work, defending the attendees and convention infrastructure. We innovated by giving the Agentic SOC entry to Endace’s always-on, full packet seize, and requested the agent to evaluate a possible SharpHound Recon assault that we had seen whereas menace searching. Inside minutes, the agent returned an correct and descriptive evaluation of the menace, concluding that it was a benign close to miss. This saved us many hours of labor, giving us confidence that the Agentic SOC can be an enormous increase to safety and productiveness. This weblog explores how we constructed the integrations and the way AI helped us with our menace hunt and menace evaluation.

Full Packet Knowledge – A gold mine for Agentic AI

At Cisco Reside AMER 2026 we deployed always-on, full packet seize as a supply of forensic proof, built-in with Agentic AI, to assist the convention SOC directives of Shield, Educate, and Innovate. All the time-on, full packet seize supplies distinctive perception into all exercise on the community, delivering important context and proof for Incident Response and Risk Searching groups, in addition to an unmatched knowledge lake of all community exercise for the emergent Agentic SOC.

The problem when human analysts analyze packet knowledge is whether or not they have the experience and expertise to interpret and perceive what packets are telling them: as a result of not everyone seems to be a packet guru.

To make full use of this wealthy community knowledge, we determined to combine Endace full packet seize with the Agentic AI capabilities constructed into Cisco XDR and Splunk Enterprise Safety, together with our customized agentic device. The aim was to empower our incident responders with highly effective proof and reasoning to expedite the decision-making for suspicious exercise. A few of our analysts have been spending their first day ever in a SOC, so our aim was to assist them be productive rapidly utilizing Agentic AI. This was additionally a fantastic alternative to grasp how Agentic AI helps productiveness within the SOC.

Agentic AI Augmented Structure

Our Agentic SOC Structure is a pure evolution of the SOC Structure we’ve been deploying for the final a number of years, closely leveraging telemetry and insights derived from community knowledge we monitor, analyze and seize all through every occasion. We depend on logs generated by Cisco Firepower, Safe Community Analytics, Safe Entry, AI Protection, Splunk Assault Analyzer, Safe Malware Analytics, and EndaceProbe (which additionally generates Zeek logs and reconstructs file content material from the packet knowledge it information). Splunk Enterprise Safety was the repository for all these logs and knowledge, whereas EndaceProbe was the repository for full packet knowledge for the whole week of the occasion.

We carried out a Mannequin Context Protocol (MCP) server for Endace to combine with Cisco Cloud Management, permitting us to construct Agentic AI integrations with Splunk, Cisco XDR and different elements of the SOC (see Baz Shaw’s weblog for extra element: Cisco Reside 2026 – Utilizing LLMs and Endace Full Packet Seize for Incident Response).

With the Endace MCP server in place, we constructed a light-weight Agentic Tier-2 SOC analyst that consumes a single XDR incident and investigates it end-to-end. It builds on the agentic capabilities already in our merchandise. Below the hood, it combines the Endace MCP (for packet seize and decode) with a Splunk MCP (for querying the Zeek logs and different indexes) and the Cisco XDR APIs (for incident, asset, and observable context), all orchestrated by a reasoning agent that we tailor-made with Cisco Reside context — the venue’s IP ranges, the Splunk index structure, and the SOC’s guidelines of engagement. The result’s a single entry level: give it an incident ID, and it pulls the XDR context, retrieves the related Endace packets, runs focused Splunk queries, and returns a structured report. (For the total structure of the device and the way we constructed it, see the deep-dive: “AIM — Constructing an Agentic Tier-2 SOC Analyst at Cisco Reside AMER 2026.”)

Investigating a Potential SharpHound Assault

At every SOC occasion we spend a few of our time being curious and menace looking for suspicious exercise. Beforehand we had seen insecure AD as a critical menace to some attendees at one other Cisco Reside occasion, so we determined to take one other look, first utilizing people fairly than Brokers.

Reviewing the packet knowledge from three days of convention exercise, we rapidly discovered a number of LDAP periods initiated within the clear by attendee gadgets. In whole, 48 gadgets have been making an attempt to provoke LDAP binds to exterior LDAP servers utilizing each IPv4 and IPv6 addresses.

The high-profile group names discovered within the LDAP bind requests have been notably regarding. We theorized that the conduct of steady makes an attempt at nameless binds could also be an indication of SharpHound reconnaissance. This recon, if profitable, may end up in LDAP enumeration exposing delicate particulars that could be used to compromise a corporation.

Agentic AI Massively Speeds our Evaluation

At this level, we determined to make use of Agentic AI capabilities to analyze and assess this potential menace. Our first step was to create an incident in Cisco XDR. The incident included an outline, the incident time, and an IP tuple and port. Then the XDR Assault Storyboard kicked in as the first agent, delivering an automated first-pass evaluation of the incident. Constructing on high of that evaluation, our Tier-2 agent (AIM) took it additional — working the incident in phases and deciding every subsequent step based mostly on what the earlier one returned (actually agentic). First, it learn the XDR incident context, then pivoted to Endace full packet seize to tug the precise LDAP/389 session (inside an analyst-approved 15-minute seize window) after which gathered extra supporting proof from Splunk logs, all autonomously.

Inside a couple of minutes we have been introduced with a well-written report that described the incident, knowledge gathered, reasoning, evaluation, and disposition together with the subsequent steps. For first-time analysts particularly, this was a goldmine — the Agent interpreted the packets by itself, doing the arduous half. As SOC analysts, we may overview the Agent’s work and take the subsequent steps.

The Agent additionally produced step-by-step execution logs; each question and determination — so the total reasoning path could be handed to Tier-3 if escalation is ever wanted — displaying precisely the way it reached its conclusion. It even zoomed out to examine different attendees within the later time window: a blast-radius examine, completed mechanically. On this case, the incident was benign, and the advice was to shut it as a benign/near-miss. As a result of we offer the Agent with entry to All the time-On, full packet knowledge, it was capable of overview all packet knowledge to map out the blast radius solely and assess all incidents of this menace.

Constructing Expertise

It was notably encouraging to see the agent first fail, then be taught from its mistake. Initially it blended up “occasion time” and “first-seen” time. On the primary go, it discovered no packet proof as a result of it was trying to find the incorrect time interval. On the second go, it realized to make use of the “first-seen” time, discovered the packet proof, and wrote that lesson again into its talent file so it might know for subsequent time.

Conclusion

The Agentic SOC, mixing Agentic AI constructed into Endace’s merchandise with customized agentic instruments, is an enormous increase to productiveness and safety. The well-reasoned assessments it supplies enable us people to make quick and sturdy choices. This, in flip, permits us to focus our treasured time on probably the most critical threats.

Acknowledgements

Our thanks go to the Cisco SOC group led by @Jessica Oppenheimer and @Ivan Berlinson for the chance to combine EndaceProbes with the Cisco Reside Agentic SOC structure. The SOC group is a group of Cisco and Splunk specialists throughout many domains who have been a pleasure to work and innovate with, and we got here away with a fantastic appreciation for the ability of the Cisco Safety and Splunk instruments. The Endace and Cisco groups have been capable of show out integration improvements and take a look at them in earnest in a real-world surroundings in preparation for making them typically accessible to the market.

Take a look at the blogs by the engineers who labored contained in the SOC at Las Vegas:



Supply hyperlink

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleChocolate Chip Zucchini Bread – WellPlated.com
Next Article Understanding Butyrate – The Key to Optimum Well being and Nicely-Being
Shape Perfeito
  • Website

Related Posts

A Case for Exterior Reference Pricing in Healthcare  – The Well being Care Weblog

July 29, 2026

Joe Rogan’s New British Crush

July 27, 2026

Antares and the Associate Alternative: Native, Environment friendly, Trusted AI for Safety

July 26, 2026

What Well being Tech Traders Love in Founders — and What They Can’t Stand

July 25, 2026

Healthcare Has Confused Disclosure With Understanding – The Well being Care Weblog

July 23, 2026

Trump Is Caught within the Entice He Set

July 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss

Trilivy Assessment: Optavia’s New Identification

By Shape PerfeitoJuly 29, 2026

Should you’ve seen the title Trilivy pop up on social media recently, don’t fear –…

Merrell MTL SpeedArc Peak Assessment – iRunFar

July 29, 2026

Breathe in Yoga: When to Inhale and Exhale (Pranayama Fundamentals) – Fitsri Yoga

July 29, 2026

Wholesome Highway Journey Meals for the RV: 40 Simple Vegan Recipes

July 29, 2026

Subscribe to Updates

Get the latest creative news from Shapeperfeito about health, fitness and healthy lifestyle.

Please enable JavaScript in your browser to complete this form.
Loading
About Us
About Us

At ShapePerfeito, we believe that true fitness goes beyond workouts and diets — it’s a lifestyle. Our mission is to empower individuals from all walks of life to take charge of their well-being with practical, science-backed guidance and positive motivation.

Our Picks

Wholesome Highway Journey Meals for the RV: 40 Simple Vegan Recipes

July 29, 2026

A Case for Exterior Reference Pricing in Healthcare  – The Well being Care Weblog

July 29, 2026

Shrimp and Broccoli

July 28, 2026
USEFUL LINKS
  • About
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • About
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Shapeperfeito.All Right Reserved.

Type above and press Enter to search. Press Esc to cancel.